First published: Tue May 21 2024(Updated: )
IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege. IBM X-Force ID: 284563.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM OS/400 | <=7.5 | |
IBM OS/400 | <=7.4 | |
IBM OS/400 | <=7.3 | |
IBM OS/400 | <=7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-27264 has a critical severity rating due to the potential for local users to gain elevated privileges.
To fix CVE-2024-27264, update the IBM Performance Tools for i to the latest version provided by IBM.
CVE-2024-27264 affects local users on IBM Performance Tools for i versions 7.2 through 7.5.
An attacker exploiting CVE-2024-27264 could execute user-controlled code with administrator privileges.
CVE-2024-27264 can be exploited by a local user without requiring additional user interaction.